Updated CoolClient Malware Uses Signed Windows Rootkit For Advanced Stealth

Published:

Kaspersky has identified a new version of the CoolClient backdoor linked to the threat actor known as HoneyMyte, also referred to as Mustang Panda, that introduces a signed Windows kernel mode rootkit designed to improve stealth and persistence on compromised systems. According to the cybersecurity company, the latest malware variant has been observed targeting victims in Myanmar, Mongolia, Pakistan and Russia, including confirmed government organizations. In the investigated attacks, CoolClient was consistently deployed as a secondary backdoor following an initial PlugX infection. Kaspersky stated that while the malware retains much of the execution flow seen in previous CoolClient variants, it now includes a previously undocumented kernel mode driver capable of hiding malicious processes, files, registry objects and command and control network information from security tools. The company has also published file hashes, file paths and command and control domains as indicators of compromise to help defenders identify affected systems. 

According to Kaspersky, the malicious kernel component is deployed only when the malware has sufficient privileges, including full access to the Windows Service Control Manager and the SeTcbPrivilege privilege. If those permissions are unavailable, the malware skips installation of the driver and continues with the final stage payload. When deployment is possible, the malware extracts an embedded LZMA compressed driver, saves it as msagent.sys and installs it as a Windows service named msagent. The driver is digitally signed using a certificate issued to Nanjing Ranyi Technology Co., Ltd., which was valid between August 2013 and September 2014. Kaspersky noted that several older malicious drivers signed with the same certificate were identified, although there is currently no direct evidence linking those earlier samples to the latest CoolClient campaign. Once loaded, the driver communicates directly with the user mode backdoor using input output control requests that register the malware process as trusted, transfer command and control server addresses and identify files and registry locations that should remain hidden and protected from security software.

The investigation found that CoolClient provides a broad range of espionage capabilities, including keylogging, clipboard theft, credential harvesting, file management, system reconnaissance and plugin based extensions. In one campaign targeting Myanmar, HoneyMyte used PlugX as the initial post compromise implant before deploying CoolClient. The attackers reportedly added Microsoft Defender exclusions for a fake Windows Defender directory, copied malicious components into the folder and renamed a legitimate Sangfor application to defender.exe to perform DLL sideloading. The malware established persistence by creating a scheduled task that launched the application with SYSTEM privileges whenever Windows started. During execution, the legitimate application loaded a malicious library named libngs.dll, which decrypted and executed another component called loadcert.ini. That component managed persistence, registry modifications, User Account Control bypass, process injection, driver deployment and the loading of the final cert.ini implant responsible for command and control communications. Kaspersky also observed that the malware created an AutoRun registry entry named goopdate, installed a Windows service called media updaten and used remote procedure call based process creation together with parent process ID spoofing before injecting malicious code into a process named synchost.exe.

Once active, the kernel mode rootkit significantly expands the malware’s ability to evade detection. Kaspersky reported that the driver stores its stealth configuration in the Windows registry and registers callbacks that hide protected processes, registry keys, files and directories while preventing modification or deletion. It can also reduce access rights when other applications attempt to interact with protected processes, making termination or code injection much more difficult. The rootkit additionally hides selected processes from the Windows active process list, filters protected files through a filesystem minifilter and conceals registry entries from security tools. Another feature filters configured command and control IP addresses from Windows network information returned to user applications. Although the driver supports 33 different input output control handlers, Kaspersky observed only three being used during normal execution. The findings build upon earlier Kaspersky research published in January 2026, which documented another CoolClient variant targeting Pakistan and Myanmar with a previously unseen rootkit, as well as research from December 2025 describing a different HoneyMyte kernel mode rootkit used to deploy the ToneShell backdoor. According to Kaspersky, the latest driver shares similarities with previous HoneyMyte malware while introducing dedicated communication mechanisms between the rootkit and the CoolClient backdoor to improve operational stealth on infected Windows systems.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img